dual dns
providing additional
resiliency when vulnerabilities surface

TCPWave provides appliances with two flavors of
DNS. An intelligent watchdog keeps performing an
automated health check on the running DNS
process. We have a smart logic, which can be
pre-configures to take an appropriate decision
when the primary DNS software (BIND) is not
responding. When a DDOS attack makes BIND non
responsive, the health check would trigger an
SNMP trap to the customer's fault management
console; and would then switch to a non-BIND
based version of DNS. Hooks are built into BIND
and the non-BIND version to Quagga BGP so that
the appliance will not attract traffic when DNS
is down. This is also known as blackhole
prevention. TCPWave also reports the
capacity planning metrics and the overall health
of the appliance via SNMP.
Contact us for
additional information.